Gentoo Archives: gentoo-commits

From: Thomas Deutschmann <whissi@g.o>
To: gentoo-commits@l.g.o
Subject: [gentoo-commits] repo/gentoo:master commit in: app-admin/rsyslog/
Date: Thu, 18 Apr 2019 01:37:42
Message-Id: 1555551235.6bda7fd868e9b88da0ba15f41faf7df190cbcf22.whissi@gentoo
1 commit: 6bda7fd868e9b88da0ba15f41faf7df190cbcf22
2 Author: Thomas Deutschmann <whissi <AT> gentoo <DOT> org>
3 AuthorDate: Thu Apr 18 01:33:44 2019 +0000
4 Commit: Thomas Deutschmann <whissi <AT> gentoo <DOT> org>
5 CommitDate: Thu Apr 18 01:33:55 2019 +0000
6 URL: https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=6bda7fd8
7
8 app-admin/rsyslog: bump to v8.1904.0
9
10 Package-Manager: Portage-2.3.62, Repoman-2.3.12
11 Signed-off-by: Thomas Deutschmann <whissi <AT> gentoo.org>
12
13 app-admin/rsyslog/Manifest | 2 +
14 app-admin/rsyslog/rsyslog-8.1904.0.ebuild | 465 ++++++++++++++++++++++++++++++
15 2 files changed, 467 insertions(+)
16
17 diff --git a/app-admin/rsyslog/Manifest b/app-admin/rsyslog/Manifest
18 index 724cd893dde..dd497e90df6 100644
19 --- a/app-admin/rsyslog/Manifest
20 +++ b/app-admin/rsyslog/Manifest
21 @@ -1,10 +1,12 @@
22 DIST rsyslog-8.1901.0.tar.gz 2750872 BLAKE2B 8bc07bd0c73cf309b5fb853e3bc66e555dee4284d0c8ede5b73420db7b42758f5fcfbc7ca90b618cc27e7067795f2725f5ed96f59170f3d2690a0653f2b69847 SHA512 2b8b2d40d3df4c47dba765d70fc716dc127ce776b31f217f78a3e1c2bf820e41799a5069d7f41f04ce39baead286ecd42fb353492873e3795aff704d686d67cb
23 DIST rsyslog-8.1903.0.tar.gz 2786605 BLAKE2B 2c60450b5f5a54f3d4fe4f9f51c81145cdebb1b0e1dd4b76f2ad23803c8bb417affbdcc9b4a0d8ccb65b0e98f5cb5cf187ce219be3e44e44c5bd253cae5f95dc SHA512 0f698c264a4afba56467b341c094be7357fba08a6ee7a24bb1b053c06da04e83eb1832ee46b68ea21f8f4de841cd97aaadc46e78bb4adfe23604c9fe95103fa9
24 +DIST rsyslog-8.1904.0.tar.gz 2902708 BLAKE2B 515d5e32c2dc6cdd8dd51fc595ad775503438603f28828e9f1a427b184a5a61de32af2ee90334b7d56a9404106d74da47386a18a370278d5a16422a6bb09f556 SHA512 cccb48f06508d7e7c2dd788903f4d7ddb3020cdf6079aea1d52387c56b920f10b08957a79b5d420ccdb54cae50d1da6e5eb80cde9498bceaeda4f6ce37f694fd
25 DIST rsyslog-8.38.0.tar.gz 2721798 BLAKE2B 578bc9eefce4893a9c1eb54ee7360cd9fa51b3c87ffe07a0fd5b122987f991835f603417243084de0b59286e993ad1c84237e61c44bc18457b3660668421101b SHA512 9dc3bdc4ef01c2af433478e182704694cb50849d811d476a03e4ce03b3c5aecfb506e7f1c1e51fadcd63da60b067d8011b92b8c9354a688fe66f7b6ffd8f9254
26 DIST rsyslog-8.39.0.tar.gz 2721560 BLAKE2B 0680cb31d0a07e5676a5c5626e46fa174b8df08ceec49b514624ff8ffeb750bbf199f73af1d89b9dfad121a292084d75b0a1218fb33138f1d7a149fd730cb3d9 SHA512 f46ead433f703df4af6ddc4bbb178ea145d7d2a35ee7749c32b9889f299ba20c83ed76c246530608198e84fef1f2bf10097344c31d5df38b9e0ae47cf4bee479
27 DIST rsyslog-8.40.0.tar.gz 2726022 BLAKE2B 33f7f2018200a20b01dbfabeeab592aa09d530edd313bb13f16c47cf3f67aebd9c465af3f1e468ca3d352cd83e4f4eee567c6fd54bbaee1723bee56f4631b440 SHA512 3d5d4f92e37ad9bf3767d5d7fc87fcb7956656f676a9495c78abd12fe9072ec8763b50543b198308a71d5d919721fb9b84b6725dd83a9d9b8a1639d81382c0dd
28 DIST rsyslog-doc-8.1901.0.tar.gz 7768575 BLAKE2B 40bc8b038fd0210d0cac01704624d87c2a73701a7494e5970423adf14948e46d1cff6df5894a82e6664d891d0c2760a5a0154bc42fb410ecf6dd25f3166e17b8 SHA512 afcc592ce4bf0dbe048786627d87b783f1c99e7711c44ffcc41cde67b2b2fef55c944b5c90e7272a84bbec95b78c0174df634b02baad2ac5819b3611efc1cb98
29 DIST rsyslog-doc-8.1903.0.tar.gz 7816457 BLAKE2B 0628a5e7f0a2c8229470f6b05c22fa0d01de12eace4f895e17a47e7003bf078be5f3b2df15cd13a4cf53384d285b558b0936308cb58e7c7e71796ca99447da3e SHA512 b42f950499798fd2bbf9e2ac2da074781955cc552628edcd928f25943b6b80d5f2e1a2eab3b8fb0fa2f6278f2b4366f096c3e976a91223e545b4306479ca4f5d
30 +DIST rsyslog-doc-8.1904.0.tar.gz 8042650 BLAKE2B 585fe5c63eee1fb46f94dcd3d529045b3900e08c291e0e71ed9bf32a6200e6c7283820b262bd56e9aeb74cc227ecd518caafec5a8f87c1d8523d5d7fd95030aa SHA512 da0ff00fbe71756b3c27fd8b94e88611452c3ba611e583862556393faaaa596ca8f32f694ad40a3e1df67385d9f9ca80db6a58f5d2e336fe95639dd7cd0de828
31 DIST rsyslog-doc-8.38.0.tar.gz 7662314 BLAKE2B 57a121950a3f6630e4736a1ff998e93b543389107d146ddb148ecd2702bb208d21a7f4d77f2fd958f2a56e092341fc6a24ed1cc80a910cb1adb54c65b5b2da04 SHA512 e28a09ae2fcddc711d2cfd31207c9862192598e49964a47b41fc8fa3ae5b1e08b7e2589fb5af859d58d4bf028574eb56cac6514401aa56cb482fa1166863e6a5
32 DIST rsyslog-doc-8.39.0.tar.gz 7674833 BLAKE2B 1526e0637c3ab9846f447dcea48efbfd17aa517c2fc875c46ac190428db6aa2a0f81f8aaed6e5b0b6991a5c13f45bc818be76c0fe4444c0eb45628ebf48b4956 SHA512 a6d09d384616a264fdf6e09fa0f61bd82a42340bac426d93119e11158f293dd58f894623aca30f2137e51bf701531f07938d014c9b8ec97d0a796447de3089de
33 DIST rsyslog-doc-8.40.0.tar.gz 7709769 BLAKE2B cda3bbd005120e7100bb36cf4c0f99d3a037525c5451ead5957f4dfe06eaceeba8fb2e266f53203bee6fae97898774ee17862a52ca1dae99aeb3534bbfadcd60 SHA512 2e2f37336948984a8cf0e098eb46e61fe4de6366d63a98204ecd558f4e21b7c1f222659f7bdecdd22e0a61d34c442b4734dbe72a72e8716c768a900b954d473f
34
35 diff --git a/app-admin/rsyslog/rsyslog-8.1904.0.ebuild b/app-admin/rsyslog/rsyslog-8.1904.0.ebuild
36 new file mode 100644
37 index 00000000000..c745aa8c516
38 --- /dev/null
39 +++ b/app-admin/rsyslog/rsyslog-8.1904.0.ebuild
40 @@ -0,0 +1,465 @@
41 +# Copyright 1999-2019 Gentoo Authors
42 +# Distributed under the terms of the GNU General Public License v2
43 +
44 +EAPI="6"
45 +PYTHON_COMPAT=( python{2_7,3_5,3_6,3_7} )
46 +
47 +inherit autotools eutils linux-info python-any-r1 systemd
48 +
49 +DESCRIPTION="An enhanced multi-threaded syslogd with database support and more"
50 +HOMEPAGE="https://www.rsyslog.com/"
51 +
52 +if [[ ${PV} == "9999" ]]; then
53 + EGIT_REPO_URI="https://github.com/rsyslog/${PN}.git"
54 +
55 + DOC_REPO_URI="https://github.com/rsyslog/${PN}-doc.git"
56 +
57 + inherit git-r3
58 +else
59 + KEYWORDS="~amd64 ~arm ~arm64 ~hppa ~x86"
60 +
61 + SRC_URI="
62 + https://www.rsyslog.com/files/download/${PN}/${P}.tar.gz
63 + doc? ( https://www.rsyslog.com/files/download/${PN}/${PN}-doc-${PV}.tar.gz )
64 + "
65 +fi
66 +
67 +LICENSE="GPL-3 LGPL-3 Apache-2.0"
68 +SLOT="0"
69 +IUSE="curl dbi debug doc elasticsearch +gcrypt grok gnutls jemalloc kafka kerberos kubernetes libressl mdblookup"
70 +IUSE+=" mongodb mysql normalize clickhouse omhttp omhttpfs omudpspoof openssl postgres"
71 +IUSE+=" rabbitmq redis relp rfc3195 rfc5424hmac snmp ssl systemd test usertools +uuid xxhash zeromq"
72 +RESTRICT="!test? ( test )"
73 +
74 +RDEPEND="
75 + >=dev-libs/libfastjson-0.99.8:=
76 + >=dev-libs/libestr-0.1.9
77 + >=sys-libs/zlib-1.2.5
78 + curl? ( >=net-misc/curl-7.35.0 )
79 + dbi? ( >=dev-db/libdbi-0.8.3 )
80 + elasticsearch? ( >=net-misc/curl-7.35.0 )
81 + gcrypt? ( >=dev-libs/libgcrypt-1.5.3:= )
82 + grok? ( >=dev-libs/grok-0.9.2 )
83 + jemalloc? ( >=dev-libs/jemalloc-3.3.1:= )
84 + kafka? ( >=dev-libs/librdkafka-0.9.0.99:= )
85 + kerberos? ( virtual/krb5 )
86 + kubernetes? ( >=net-misc/curl-7.35.0 )
87 + mdblookup? ( dev-libs/libmaxminddb:= )
88 + mongodb? ( >=dev-libs/mongo-c-driver-1.1.10:= )
89 + mysql? ( virtual/libmysqlclient:= )
90 + normalize? (
91 + >=dev-libs/libee-0.4.0
92 + >=dev-libs/liblognorm-2.0.3:=
93 + )
94 + clickhouse? ( >=net-misc/curl-7.35.0 )
95 + omhttpfs? ( >=net-misc/curl-7.35.0 )
96 + omudpspoof? ( >=net-libs/libnet-1.1.6 )
97 + postgres? ( >=dev-db/postgresql-8.4.20:= )
98 + rabbitmq? ( >=net-libs/rabbitmq-c-0.3.0:= )
99 + redis? ( >=dev-libs/hiredis-0.11.0:= )
100 + relp? ( >=dev-libs/librelp-1.2.17:= )
101 + rfc3195? ( >=dev-libs/liblogging-1.0.1:=[rfc3195] )
102 + rfc5424hmac? (
103 + !libressl? ( >=dev-libs/openssl-0.9.8y:0= )
104 + libressl? ( dev-libs/libressl:= )
105 + )
106 + snmp? ( >=net-analyzer/net-snmp-5.7.2 )
107 + ssl? (
108 + gnutls? ( >=net-libs/gnutls-2.12.23:0= )
109 + openssl? (
110 + !libressl? ( dev-libs/openssl:0= )
111 + libressl? ( dev-libs/libressl:0= )
112 + )
113 + )
114 + systemd? ( >=sys-apps/systemd-234 )
115 + uuid? ( sys-apps/util-linux:0= )
116 + xxhash? ( dev-libs/xxhash:= )
117 + zeromq? (
118 + >=net-libs/czmq-3.0.2
119 + )"
120 +DEPEND="${RDEPEND}
121 + >=sys-devel/autoconf-archive-2015.02.24
122 + virtual/pkgconfig
123 + elibc_musl? ( sys-libs/queue-standalone )
124 + test? (
125 + >=dev-libs/liblogging-1.0.1[stdlog]
126 + jemalloc? ( <sys-libs/libfaketime-0.9.7 )
127 + !jemalloc? ( sys-libs/libfaketime )
128 + ${PYTHON_DEPS}
129 + )"
130 +
131 +REQUIRED_USE="
132 + kubernetes? ( normalize )
133 + ssl? ( || ( gnutls openssl ) )
134 +"
135 +
136 +if [[ ${PV} == "9999" ]]; then
137 + DEPEND+=" doc? ( >=dev-python/sphinx-1.1.3-r7 )"
138 + DEPEND+=" >=sys-devel/flex-2.5.39-r1"
139 + DEPEND+=" >=sys-devel/bison-2.4.3"
140 + DEPEND+=" >=dev-python/docutils-0.12"
141 +fi
142 +
143 +CONFIG_CHECK="~INOTIFY_USER"
144 +WARNING_INOTIFY_USER="CONFIG_INOTIFY_USER isn't set. Imfile module on this system will only support polling mode!"
145 +
146 +pkg_setup() {
147 + use test && python-any-r1_pkg_setup
148 +}
149 +
150 +src_unpack() {
151 + if [[ ${PV} == "9999" ]]; then
152 + git-r3_fetch
153 + git-r3_checkout
154 + else
155 + unpack ${P}.tar.gz
156 + fi
157 +
158 + if use doc; then
159 + if [[ ${PV} == "9999" ]]; then
160 + local _EGIT_BRANCH=
161 + if [[ -n "${EGIT_BRANCH}" ]]; then
162 + # Cannot use rsyslog commits/branches for documentation repository
163 + _EGIT_BRANCH=${EGIT_BRANCH}
164 + unset EGIT_BRANCH
165 + fi
166 +
167 + git-r3_fetch "${DOC_REPO_URI}"
168 + git-r3_checkout "${DOC_REPO_URI}" "${S}"/docs
169 +
170 + if [[ -n "${_EGIT_BRANCH}" ]]; then
171 + # Restore previous EGIT_BRANCH information
172 + EGIT_BRANCH=${_EGIT_BRANCH}
173 + fi
174 + else
175 + cd "${S}" || die "Cannot change dir into '${S}'"
176 + mkdir docs || die "Failed to create docs directory"
177 + cd docs || die "Failed to change dir into '${S}/docs'"
178 + unpack ${PN}-doc-${PV}.tar.gz
179 + fi
180 + fi
181 +}
182 +
183 +src_prepare() {
184 + default
185 +
186 + # https://github.com/rsyslog/rsyslog/issues/3626
187 + sed -i \
188 + -e '\|^#!/bin/bash$|a exit 77' \
189 + tests/mmkubernetes-cache-expir*.sh \
190 + || die "Failed to disabled known test failure mmkubernetes-cache-expir*.sh"
191 +
192 + eautoreconf
193 +}
194 +
195 +src_configure() {
196 + # Maintainer notes:
197 + # * Guardtime support is missing because libgt isn't yet available
198 + # in portage.
199 + # * Hadoop's HDFS file system output module is currently not
200 + # supported in Gentoo because nobody is able to test it
201 + # (JAVA dependency).
202 + # * dev-libs/hiredis doesn't provide pkg-config (see #504614,
203 + # upstream PR 129 and 136) so we need to export HIREDIS_*
204 + # variables because rsyslog's build system depends on pkg-config.
205 +
206 + if use redis; then
207 + export HIREDIS_LIBS="-L${EPREFIX}/usr/$(get_libdir) -lhiredis"
208 + export HIREDIS_CFLAGS="-I${EPREFIX}/usr/include"
209 + fi
210 +
211 + local myeconfargs=(
212 + --disable-debug-symbols
213 + --disable-generate-man-pages
214 + --without-valgrind-testbench
215 + --disable-liblogging-stdlog
216 + $(use_enable test testbench)
217 + $(use_enable test libfaketime)
218 + $(use_enable test extended-tests)
219 + # Input Plugins without depedencies
220 + --enable-imdiag
221 + --enable-imfile
222 + --enable-impstats
223 + --enable-imptcp
224 + # Message Modificiation Plugins without depedencies
225 + --enable-mmanon
226 + --enable-mmaudit
227 + --enable-mmcount
228 + --enable-mmfields
229 + --enable-mmjsonparse
230 + --enable-mmpstrucdata
231 + --enable-mmrm1stspace
232 + --enable-mmsequence
233 + --enable-mmutf8fix
234 + # Output Modification Plugins without dependencies
235 + --enable-mail
236 + --enable-omprog
237 + --enable-omruleset
238 + --enable-omstdout
239 + --enable-omuxsock
240 + # Misc
241 + --enable-fmhash
242 + $(use_enable xxhash fmhash-xxhash)
243 + --enable-pmaixforwardedfrom
244 + --enable-pmciscoios
245 + --enable-pmcisconames
246 + --enable-pmlastmsg
247 + $(use_enable normalize pmnormalize)
248 + --enable-pmnull
249 + --enable-pmpanngfw
250 + --enable-pmsnare
251 + # DB
252 + $(use_enable dbi libdbi)
253 + $(use_enable mongodb ommongodb)
254 + $(use_enable mysql)
255 + $(use_enable postgres pgsql)
256 + $(use_enable redis omhiredis)
257 + # Debug
258 + $(use_enable debug)
259 + $(use_enable debug diagtools)
260 + $(use_enable debug valgrind)
261 + # Misc
262 + $(use_enable clickhouse)
263 + $(use_enable curl fmhttp)
264 + $(use_enable elasticsearch)
265 + $(use_enable gcrypt libgcrypt)
266 + $(use_enable jemalloc)
267 + $(use_enable kafka imkafka)
268 + $(use_enable kafka omkafka)
269 + $(use_enable kerberos gssapi-krb5)
270 + $(use_enable kubernetes mmkubernetes)
271 + $(use_enable normalize mmnormalize)
272 + $(use_enable mdblookup mmdblookup)
273 + $(use_enable grok mmgrok)
274 + $(use_enable omhttp)
275 + $(use_enable omhttpfs)
276 + $(use_enable omudpspoof)
277 + $(use_enable rabbitmq omrabbitmq)
278 + $(use_enable relp)
279 + $(use_enable rfc3195)
280 + $(use_enable rfc5424hmac mmrfc5424addhmac)
281 + $(use_enable snmp)
282 + $(use_enable snmp mmsnmptrapd)
283 + $(use_enable gnutls)
284 + $(use_enable openssl)
285 + $(use_enable systemd imjournal)
286 + $(use_enable systemd omjournal)
287 + $(use_enable usertools)
288 + $(use_enable uuid)
289 + $(use_enable zeromq imczmq)
290 + $(use_enable zeromq omczmq)
291 + --with-systemdsystemunitdir="$(systemd_get_systemunitdir)"
292 + )
293 +
294 + econf "${myeconfargs[@]}"
295 +}
296 +
297 +src_compile() {
298 + default
299 +
300 + if use doc && [[ "${PV}" == "9999" ]]; then
301 + einfo "Building documentation ..."
302 + local doc_dir="${S}/docs"
303 + cd "${doc_dir}" || die "Cannot chdir into \"${doc_dir}\"!"
304 + sphinx-build -b html source build || die "Building documentation failed!"
305 + fi
306 +}
307 +
308 +src_test() {
309 + local _has_increased_ulimit=
310 +
311 + # Sometimes tests aren't executable (i.e. when added via patch)
312 + einfo "Adjusting permissions of test scripts ..."
313 + find "${S}"/tests -type f -name '*.sh' \! -perm -111 -exec chmod a+x '{}' \; || \
314 + die "Failed to adjust test scripts permission"
315 +
316 + if ulimit -n 3072; then
317 + _has_increased_ulimit="true"
318 + fi
319 +
320 + if ! emake --jobs 1 check; then
321 + eerror "Test suite failed! :("
322 +
323 + if [[ -z "${_has_increased_ulimit}" ]]; then
324 + eerror "Probably because open file limit couldn't be set to 3072."
325 + fi
326 +
327 + if has userpriv ${FEATURES}; then
328 + eerror "Please try to reproduce the test suite failure with FEATURES=-userpriv " \
329 + "before you submit a bug report."
330 + fi
331 +
332 + fi
333 +}
334 +
335 +src_install() {
336 + local DOCS=(
337 + AUTHORS
338 + ChangeLog
339 + "${FILESDIR}"/README.gentoo
340 + )
341 +
342 + use doc && local HTML_DOCS=( "${S}/docs/build/." )
343 +
344 + default
345 +
346 + newconfd "${FILESDIR}/${PN}.confd-r1" ${PN}
347 + newinitd "${FILESDIR}/${PN}.initd-r1" ${PN}
348 +
349 + keepdir /var/empty/dev
350 + keepdir /var/spool/${PN}
351 + keepdir /etc/ssl/${PN}
352 + keepdir /etc/${PN}.d
353 +
354 + insinto /etc
355 + newins "${FILESDIR}/${PN}.conf" ${PN}.conf
356 +
357 + insinto /etc/rsyslog.d/
358 + newins "${FILESDIR}/50-default-r1.conf" 50-default.conf
359 +
360 + insinto /etc/logrotate.d/
361 + newins "${FILESDIR}/${PN}-r1.logrotate" ${PN}
362 +
363 + if use mysql; then
364 + insinto /usr/share/doc/${PF}/scripts/mysql
365 + doins plugins/ommysql/createDB.sql
366 + fi
367 +
368 + if use postgres; then
369 + insinto /usr/share/doc/${PF}/scripts/pgsql
370 + doins plugins/ompgsql/createDB.sql
371 + fi
372 +
373 + prune_libtool_files --modules
374 +}
375 +
376 +pkg_postinst() {
377 + local advertise_readme=0
378 +
379 + if [[ -z "${REPLACING_VERSIONS}" ]]; then
380 + # This is a new installation
381 +
382 + advertise_readme=1
383 +
384 + if use mysql || use postgres; then
385 + echo
386 + elog "Sample SQL scripts for MySQL & PostgreSQL have been installed to:"
387 + elog " /usr/share/doc/${PF}/scripts"
388 + fi
389 +
390 + if use ssl; then
391 + echo
392 + elog "To create a default CA and certificates for your server and clients, run:"
393 + elog " emerge --config =${PF}"
394 + elog "on your logging server. You can run it several times,"
395 + elog "once for each logging client. The client certificates will be signed"
396 + elog "using the CA certificate generated during the first run."
397 + fi
398 + fi
399 +
400 + if [[ ${advertise_readme} -gt 0 ]]; then
401 + # We need to show the README file location
402 +
403 + echo ""
404 + elog "Please read"
405 + elog ""
406 + elog " ${EPREFIX}/usr/share/doc/${PF}/README.gentoo*"
407 + elog ""
408 + elog "for more details."
409 + fi
410 +}
411 +
412 +pkg_config() {
413 + if ! use ssl ; then
414 + einfo "There is nothing to configure for rsyslog unless you"
415 + einfo "used USE=ssl to build it."
416 + return 0
417 + fi
418 +
419 + # Make sure the certificates directory exists
420 + local CERTDIR="${EROOT}/etc/ssl/${PN}"
421 + if [[ ! -d "${CERTDIR}" ]]; then
422 + mkdir "${CERTDIR}" || die
423 + fi
424 + einfo "Your certificates will be stored in ${CERTDIR}"
425 +
426 + # Create a default CA if needed
427 + if [[ ! -f "${CERTDIR}/${PN}_ca.cert.pem" ]]; then
428 + einfo "No CA key and certificate found in ${CERTDIR}, creating them for you..."
429 + certtool --generate-privkey \
430 + --outfile "${CERTDIR}/${PN}_ca.privkey.pem" &>/dev/null
431 + chmod 400 "${CERTDIR}/${PN}_ca.privkey.pem"
432 +
433 + cat > "${T}/${PF}.$$" <<- _EOF
434 + cn = Portage automated CA
435 + ca
436 + cert_signing_key
437 + expiration_days = 3650
438 + _EOF
439 +
440 + certtool --generate-self-signed \
441 + --load-privkey "${CERTDIR}/${PN}_ca.privkey.pem" \
442 + --outfile "${CERTDIR}/${PN}_ca.cert.pem" \
443 + --template "${T}/${PF}.$$" &>/dev/null
444 + chmod 400 "${CERTDIR}/${PN}_ca.privkey.pem"
445 +
446 + # Create the server certificate
447 + echo
448 + einfon "Please type the Common Name of the SERVER you wish to create a certificate for: "
449 + read -r CN
450 +
451 + einfo "Creating private key and certificate for server ${CN}..."
452 + certtool --generate-privkey \
453 + --outfile "${CERTDIR}/${PN}_${CN}.key.pem" &>/dev/null
454 + chmod 400 "${CERTDIR}/${PN}_${CN}.key.pem"
455 +
456 + cat > "${T}/${PF}.$$" <<- _EOF
457 + cn = ${CN}
458 + tls_www_server
459 + dns_name = ${CN}
460 + expiration_days = 3650
461 + _EOF
462 +
463 + certtool --generate-certificate \
464 + --outfile "${CERTDIR}/${PN}_${CN}.cert.pem" \
465 + --load-privkey "${CERTDIR}/${PN}_${CN}.key.pem" \
466 + --load-ca-certificate "${CERTDIR}/${PN}_ca.cert.pem" \
467 + --load-ca-privkey "${CERTDIR}/${PN}_ca.privkey.pem" \
468 + --template "${T}/${PF}.$$" &>/dev/null
469 + chmod 400 "${CERTDIR}/${PN}_${CN}.cert.pem"
470 +
471 + else
472 + einfo "Found existing ${CERTDIR}/${PN}_ca.cert.pem, skipping CA and SERVER creation."
473 + fi
474 +
475 + # Create a client certificate
476 + echo
477 + einfon "Please type the Common Name of the CLIENT you wish to create a certificate for: "
478 + read -r CN
479 +
480 + einfo "Creating private key and certificate for client ${CN}..."
481 + certtool --generate-privkey \
482 + --outfile "${CERTDIR}/${PN}_${CN}.key.pem" &>/dev/null
483 + chmod 400 "${CERTDIR}/${PN}_${CN}.key.pem"
484 +
485 + cat > "${T}/${PF}.$$" <<- _EOF
486 + cn = ${CN}
487 + tls_www_client
488 + dns_name = ${CN}
489 + expiration_days = 3650
490 + _EOF
491 +
492 + certtool --generate-certificate \
493 + --outfile "${CERTDIR}/${PN}_${CN}.cert.pem" \
494 + --load-privkey "${CERTDIR}/${PN}_${CN}.key.pem" \
495 + --load-ca-certificate "${CERTDIR}/${PN}_ca.cert.pem" \
496 + --load-ca-privkey "${CERTDIR}/${PN}_ca.privkey.pem" \
497 + --template "${T}/${PF}.$$" &>/dev/null
498 + chmod 400 "${CERTDIR}/${PN}_${CN}.cert.pem"
499 +
500 + rm -f "${T}/${PF}.$$"
501 +
502 + echo
503 + einfo "Here is the documentation on how to encrypt your log traffic:"
504 + einfo " https://www.rsyslog.com/doc/rsyslog_tls.html"
505 +}